ã€ã³ã¿ãŒãããã®ã¹ãã£ã³ã¯éåžžã«ç°¡åã§ããã³ã³ãã¥ãŒã¿ãŒã®åã«åº§ã£ãŠãã³ãã³ãã©ã€ã³ã§ã³ã³ãœãŒã«ãèµ·åãããµããããã¢ãã¬ã¹ãå ¥åããŸãã ãããŠãç»é¢ãã©ã®ããã«ããŒã¿ã§æºããããŠããããèŠããšããã¹ãŠã®è¡ãå®è¡ãããããã«å®è¡ãããŸãã ãã®çµæãç°ãªãIPã¢ãã¬ã¹ãæã€éããŠããããã€ã¹ããŒãã®ãªã¹ããååŸããŸãã

ä¿è·ã®ã³ã³ããã¹ãã§ã€ã³ã¿ãŒããããã¹ãã£ã³ããçç± ã»ãã¥ãªãã£ã®åé¡ãå¿é ãªå Žåã¯ããããå®è¡ããŠæ¬¡ã®è³ªåã®çããåŸãå¿ èŠããããŸãã
- Heartbleedè匱æ§ïŒæ»æè ãã¯ã©ã€ã¢ã³ããŸãã¯ãµãŒããŒã®ã¡ã¢ãªãèªã¿åãããµãŒããŒã®ç§å¯æå·åããŒãååŸã§ããããã«ããæå·åãœãããŠã§ã¢ã®ãšã©ãŒïŒã®åœ±é¿ãåããã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã¯ããã€ã§ããïŒ
- NTPãµãŒããŒãžã®æ»æã匷åããããã«äœå°ã®ã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ã䜿çšã§ããŸããïŒ
- D-Linkã«ãŒã¿ãŒã®è匱æ§ã«ãããå±éºã«ãããããŠããã·ã¹ãã ã¯ããã€ãããŸããïŒ
- 䜿çšããããã¹ãŠã®SSL蚌ææžã®æŠèŠã
ç¹å®ã®ãããã¯ãŒã¯ãæ©åšã®è匱æ§ãèŠã€ããããã®æ¢åã®ããŒã«ã¯ããªãé ãã§ããã倧éã¹ãã£ã³ãè¡ããšã100,000ãè¶ ããããã€ã¹ã®è匱æ§ç¹æ§ãååã«è¿ éã«ååŸã§ããŸãã 解決ããå¿ èŠãããéèŠãªåé¡ã¯ãDDOSæ»æäžã«NTPãµãŒããŒãšéä¿¡ããããã«äœ¿çšãããæ©åšã®èå¥ã§ãã Dãªã³ã¯ã«ãŒã¿ãŒã«ã¯åŒ·åãªä¿è·æ©èœããªããããå€ãã®å®¶åºçšæ©åšã¯è匱ã§ãã D-linkãããã¯ãŒã¯ãèŠãŠãè匱æ§ãæªçšããããããããã·ã¹ãã ã®æ°ã確èªããŠãã ããã SSL蚌ææžã®ã¹ãã£ã³ã¯ããšã©ãŒãè匱æ§ãçããããå€ã蚌ææžãèå¥ããããã«ã圹ç«ã¡ãŸãã ãããã£ãŠããæãå·®ã䌞ã¹ããããšãã§ãããã¹ãŠãã¹ãã£ã³ããããšã¯éèŠãªã¿ã¹ã¯ã§ãã
ã€ã³ã¿ãŒãããã¹ãã£ã³ã¯ãäºé²ã®ã³ã³ããã¹ãã§ãå¿ èŠã§ãã Deepnet-æ€çŽ¢ãšã³ãžã³ã«ã¯è¡šç€ºãããªãå€ãã®ã€ã³ã¿ãŒãããããŒãžãèå¥ããã®ã«åœ¹ç«ã¡ãŸãã ãããã®ããŒãžã¯ããŠãŒã¶ãŒã®èŠæ±ã«å¿ããŠçæãããæªæã®ããæ å ±ãäŒããå¯èœæ§ããããŸãã

ã-bannersããã«ã¯ã¹ãã£ã³ã³ãã³ããå®è¡ããŠãã©ã³ãã ããŒããã¹ãã£ã³ããŠã¿ãŠãã ãããæ°å以å ã«ãåé¡ãªãã¯ã©ãã¯ã§ããããšãããããŸãã
å®éãã€ã³ã¿ãŒãããã®ã¹ãã£ã³ã¯æ¬¡ã®çç±ã§äŸ¿å©ã§ãã
- 楜ããã§ãã
- ããã¯æçã§ãïŒã€ã³ã¿ãŒããããã©ãã»ã©å°ãããã¯ãã¹ãã£ã³ã³ãã³ã0.0.0.0/0ãå®è¡ããããšã§ç¢ºèªã§ããŸããã€ã³ã¿ãŒãããã«ã¯65,000ã®ããŒããããããŸããïŒã
- ããã¯ããªããæåã«ããŸãïŒ
-ã·ãŒã¡ã³ã¹å¶åŸ¡ã·ã¹ãã ãªã©ã®ã¿ãŒã²ãããéžæããŸãã
-ã€ã³ã¿ãŒããããã¹ãã£ã³ããŠãã ããã
-圌女ã®ããã«BlackHat Talkã³ã³ãã¥ãŒã¿ãŒã»ãã¥ãªãã£äŒè°ãäœæããŸãã
-ååŸããå°é家ã®ç¹æš©ã䜿çšããŸãã
ã€ã³ã¿ãŒããããã¹ãã£ã³ããããã«ç¥ã£ãŠããã¹ãããšã¯äœã§ããïŒ ãŸããç©çã€ã³ãã©ã¹ãã©ã¯ãã£ã®çè«çãªéšåãç¥ãå¿ èŠããããŸãã
- ããŒã¿ãã±ããã®ãµã€ãºã¯åºå®ãããŠããŸãã
-ã€ãŒãµããããã±ããã«ã¯44ãã€ããå«ãŸããŸãã
-TCP SYNãã±ããã«ã¯40ãã€ããå«ãŸããŸãã - 1 Gbit / sã€ãŒãµãããã®æ倧é床ïŒ
-å®éã®ãã©ãã£ãã¯ã§ã¯476 Mbpsã
-ã€ãŒãµãããæ¥ç¶ã®å Žåã¯524 Mbpsã
-1ç§ããã1,488,000ãã±ããã
ããã¯ãå®éã®ããŒã¿éã§ã¯ãªããä¿èšŒããã垯åå¹ ãã€ãŸãä¿èšŒããã垯åå¹ ã«å¯ŸããŠæéãè«æ±ãããšããäºå®ã«ããããããã€ããŒã«éæããããããšãæå³ããŸãã ããã¯ãéå°ãªãã±ãããµã€ãºã«ãããã®ã§ãã 22ãã€ããŸãã¯33ãã€ããéä¿¡ããŠãããµã€ãºã¯40ãã€ããŸãã¯44ãã€ãã®ãã±ããã«ããã¯ããããŸãŸã§ãã å®éã«ã¯1ç§éã«524ã¡ã¬ããã以äžã§è»¢éãããããããŠãŒã¶ãŒã¯1ã®ã¬ãããã§æå®ãããå®å šãªäŒé容éã«å°éããããšã¯ã»ãšãã©ãããŸããã ãã ããåºå®ãã±ãããªãŒããŒãããŒã®ãããããŒã¿ã«ã¯ããŒãžã³ãµã€ãºãããããã®ããŒãžã³ã¯ãŸã£ãã䜿çšãããŸããã ããããç§ãã¡ã¯ãããæ¯æããŸãã å®å šã«èª¿æŽãããã¹ã€ããã䜿çšããŠããå Žåã§ãããããã¯ãŒã¯ã®å šåž¯åå¹ ã䜿çšããããšã¯ã§ããŸããããããçºçããçç±ã¯ããããŸããã ã€ã³ã¿ãŒããããµãŒãã¹ã®è«æ±æžãæ¯æãã·ã¹ãã ã«ã¯æ··ä¹±ããããŸãã
ã€ã³ã¿ãŒããããããã€ããŒããã®ãã©ãã£ãã¯ãæ¯æãããã®è«æ±æžã¯ã©ã®ããã«åœ¢æãããŸããïŒ
- 1Gb /ç§ã®æ倧ã€ã³ã¿ãŒãããæ¥ç¶é床ãæäŸãããã®ããããŸãã
- ããã€ãã¯ãåäœäžã®ãããã¯ãŒã¯ã®å®éã®åž¯åå¹ ã枬å®ããçŽ600 Mbit / sã®é床ãæäŸããŸãã
- äžéšã®ã€ã³ã¿ãŒããããµãŒãã¹ãããã€ããŒã¯å°ããªãã±ãããèªèããªããããçä¿¡ãã©ãã£ãã¯ã®ã¿ããã£ããã£ããçºä¿¡ãã©ãã£ãã¯ã¯ãã£ããã£ããŸããã ããšãã°ã倧éã®æ å ±ãéä¿¡ãããããã¯ãŒã¯ããããŠã³ããŒãããæ°ã¡ã¬ãã€ããæ¯æããŸããã
- äžéšã®ãããã€ããŒã¯ãã©ãã£ãã¯ã®éããŸã£ãã枬å®ããŸãããããã¯ç§ãã¡ã«ãšã£ãŠç¹ã«èå³æ·±ããã®ã§ãã

ããšãã°ããã€ãã§ã¯ããŠãŒã¶ãŒã«100 Gb / sã®é床ãæäŸããCCCã¯ã©ãããããŸãã ãã®ãããã¯ãŒã¯ããã¹ãããããšã¯ã§ããŸããã§ããããä»å¹Žã¯10ã®ã¬ãããã€ãŒãµãããã«ãŒããæºåž¯ããŠãæ¬åœã«ãããªã®ãã確èªãããããããŸããã ãããåé¡ã¯ãéä¿¡ãããã±ãããå°ãããããšãåããããã¯ãŒã¯ã®ãã¢éã®æ¢åã®åæã«éåããããšã§ãã
ãããã¯ãŒã¯ã®ç©çã€ã³ãã©ã¹ãã©ã¯ãã£ãããã«æ€èšããŸãã
ãã©ã€ããŒãä»®æ³VPNã¯ãå°ããªãã±ããã®è² è·ã«é©å¿ã§ããŸãã ã€ãŒãµãããã¯å°ããªãã±ãããšæŠãã500 Kbpsãè¶ ããé床ã¯ãã°ãã°å°é£ã§ãã ã¹ã€ããããã®ãããªé床ã§åäœã§ããå Žåãããã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ä»ã®èŠçŽ ãããããµããŒãã§ããããšãæå³ããŸããã ãã®å ŽåããããŒå¶åŸ¡ã®ããŒã¿ãããŒãç¡å¹ã«ãããšåœ¹ç«ã¡ãŸãããã®å Žåãåä¿¡æ©ãããŒã¿ãåä¿¡ããæºåãã§ããŠããªãå Žåãéä¿¡æ©ã¯ããŒã¿è»¢éãé ãããŸãã
å Žåã«ãã£ãŠã¯ããã±ããã倱ãããå¯èœæ§ããããŸã-500 Kbpsã§ã®éä¿¡ã¯ããã¹ãŠã®ãã±ãããã€ã³ã¿ãŒãããã«å°éããããšãä¿èšŒããŸããã ã¹ãã£ã³ã«ããã䜿çšäžã®ãã±ããæ倱ã芳å¯ãããããŒããç¹å®ã§ããŸãã åãåä¿¡/éä¿¡ãæäŸããããŒãã®ã¿ã䜿çšã§ããŸãã1äžãã±ãããéä¿¡ãããšã1äžãã±ãããåä¿¡ããŸãã ãããã£ãŠãç§ã¯äž»ã«æ倧150 Kbit / sãæã«ã¯15 Kbit / sã®é床ã䜿çšããŸããããã«ããããã±ããã®æŽåæ§ã«ã€ããŠèããå¿ èŠããªããªããŸãã
èåŸ ã®èŠæ ã¯å€§ããªåé¡ã§ãã ãã®çšèªã¯ã誰ããããªããã¹ãã ãŸãã¯ãã®ä»ã®æªæã®ãã掻åã®ãœãŒã¹ãšããŠãã©ã°ãç«ãŠãããšãæå³ããŸãã å€ãã®å Žåãããã¯ãåä¿¡è ãããªãããã®æçŽãåãåããããªãããäŒç€Ÿããã®ãªã³ã¯ãæäŸããŠããªããããã¡ãŒãªã³ã°ãªã¹ãããéäŒã§ããªãå Žåã«äŒæ¥ã§çºçããŸãã ããã¯ããªãã®ã¡ãŒã«ãã¹ãã ãšããŠããŒã¯ããå šäœçãªè©å€ãå·ã€ããŸãã ããã¯ããããã¯ãŒã¯ãã¹ãã£ã³ãããšãã«çºçããå¯èœæ§ããããŸãã ããªãã¯èåŸ ã®èŠæ ãåãåãããšãã§ããããªãã®ISPã¯ããã«çå£ã«åæºããŠããŸãã ãŸãã¯ããã¡ããã®éã®åæã«éåããå Žåããã¡ããã®åœ¹å²ãæããããšã¯çŠæ¢ãããŸãã ãããããã£ãšæªãããšããããŸãïŒ
- Heartbleedè åšã¹ãã£ã³ã¯ãæ°é±éåŸã«èåŸ èŠæ ãçæããŸãããããã§ãããªãã¯è©å€ã«ææãäžããŸãã
- HTTPã¹ãã£ã³ã«ãããfail2bançŠæ¢ãªã¹ãã«éä¿¡ãããŸããã€ãŸããIPããããã¯ãããŸãã
- è åšæ€åºã«ãŒã«ã®éåSnortè åšã«ãŒã«ã¯ãå€ãã®èåŸ èŠæ ã®èŠæ ãäœæããããšãã§ããŸãã
æ¢åã®ãããã¯ãŒã¯ç£èŠæ¹æ³ã¯ãçä¿¡ãã©ãã£ãã¯ã远跡ããŸãã ã¹ãã£ã³ã䜿çšãããšãçä¿¡ãã©ãã£ãã¯ã倧ãããªããçãããããšã«ãªããŸãã ãã®æ¹æ³ã§ããã«ãŒã远跡ã§ãããšèããããŠããŸãããè¡ç¯ã®äžã®èã¿ã§å€±ãããéµãæ¢ãã®ãšåãã§ãã
ã€ã³ã¿ãŒããããµãŒãã¹ãããã€ããŒã¯äœãçå£ã«èããã¹ãã§ããïŒ ããã«ãäžéšã®ãããã¯ãŒã¯ã§ã¯ãèªåŸASãããã¯ãŒã¯å šäœã«å¯ŸããŠãã©ãã¯ããŒã«ïŒããã¹ããžã®ã«ãŒãããªããããã«ãã®ãããªã«ãŒãã£ã³ã°ã®ãã±ãããåé€ãããå Žåã®ãã©ãã«ãã«ãŒãã£ã³ã°ããªããïŒã䜿çšããŸãã
ä»ã®äººã®ã¡ãŒã«ããã¯ã¹ããã©ã€ããŒããªãããã¯ãŒã¯ã»ã°ã¡ã³ããã¹ãã£ã³ããããªããããã¹ãã£ã³ã®éã«ã¯äŸå€ã®ãªã¹ããå¿ èŠã§ãã é€å€ãªã¹ããäœæããã«ã¯ãã³ãã³ãã©ã€ã³ã§ã¹ãã£ã³ãã©ã¡ãŒã¿ãŒãèšå®ããŸãã
/etc/masscan/masscan.conf exclude = 224.0.0.0-255.255.255.255 exclude-file â exclude.ips

éèŠãªããšã¯ããããªãã¯é€å€ãªã¹ããäœæããããšã§ãã ã»ãã¥ãªãã£å°é家ã®å ¬éãªã¹ããäœæãããã®ã§ãããããã°ã©ã ãžã®åå ãªã¯ãšã¹ããéä¿¡ãã人ã®ã»ãšãã©ã¯ãéåžžããã®ãªã¹ãããåé€ããããæ±ããããŸãã 誰ããèªåã®IPã¢ãã¬ã¹ãŸãã¯äŒæ¥ãããã¯ãŒã¯ã¢ãã¬ã¹ãèŠã€ããŠããããã解èªããããšããããšãæããŠããŸãã 幞ããªããšã«ãBGPãããã¯ãŒã¯ã¯ããããã¹ãŠã®æ å ±ããããªãã¯ãã¡ã€ã³ã«ä¿æããŠãããããªãæŽç·Žããã圢åŒã§ã¬ã€ã¢ãŠããããŠããã誰ã§ãã¢ã¯ã»ã¹ã§ããŸãã ã€ã³ã¿ãŒããããã¹ãã£ã³ããŠãã¡ãªãããããã ãã§ã誰ã«ãèŠããããªãå人æ å ±ã«ã¯åœ±é¿ããªãããšãç解ããŠãã ããã æ®å¿µãªãããã»ãšãã©ã®äººã¯ã¹ãã£ã³ãšãããã³ã°ãæ··åãããããããã蚌æããå¿ èŠããããŸãã ãšã«ãããã€ã³ã¿ãŒãããå šäœãã¹ãã£ã³ã§ãããšä¿¡ããã®ã¯é£ããã§ãã
ããšãã°ãäŒç€Ÿã«ã¯ç¹å®ã®ãããã¯ãŒã¯ãããããªã¯ãšã¹ãã«å¿ããŠã¹ãã£ã³ããŸãããéèŠãªæ å ±ãä¿åããããµããããããããŸãã ãã®ãããã¹ãã£ã³ãã©ã®ããã«è¡ãããããèŠããšã圌ãã¯æããªãããé ãããããã¯ãŒã¯ãã¹ãã£ã³ããŠããããŸããŸãªããŒããšã¢ãã¬ã¹ãèŠããã®ã§ããããã³ã°ã§ããŸãïŒããšèšããŸãã
6ãæåã«èå³æ·±ã話ããããŸããã ç§ã¯ãã顧客ã®ãããã¯ãŒã¯ãã¹ãã£ã³ããŸãããã圌ãã¯å€ããããã¯ãŒã¯ãããã³ã°ã®ããã«æéãããç·æ¥äŒè°ã«ã€ããŠã®é»è©±ã§åœŒãèµ·ãããŸããã 圌ã¯ç§ã«é»è©±ããŸããããããŠç§ã¯åœŒãå®å¿ãããã¹ãã£ã³ãããã«ãŒæ»æãšã¯äœã®é¢ä¿ããªãããšã説æããªããã°ãªããŸããã§ããã å€ãã®å Žåã顧客ã¯ãã¹ãã£ã³ã®èš±å¯ãäžãããšããã«ããã€ãã®ã»ãã¥ãªãã£ã®ã£ãããéããããã«ãŒãããã«äŸµå ¥ãããšèããŠããŸãã
å¥ã®ã±ãŒã¹ã¯ããªãŒã¹ãã©ãªã¢ããã®äžäººã®ç·ã§ããã 圌ã¯ããããã¯ãŒã¯ãã¹ãã£ã³ãããšãã«ãåäžã®SYNãã±ããã®åœ¢åŒã§æ¥ç¶èŠæ±ãéä¿¡ããç§ã«é»è©±ããŠãç§ãã¡ã¯èª°ã§ãããã©ã®ãããªæ ¹æ ã§ãããè¡ã£ãŠããã®ããšèšããŸããã ç§ã¯ãã¹ãŠã説æãããã¹ãŠã®èŠå¶ãšèŠåããããµã€ãã®ã¢ãã¬ã¹ã圌ã«è©±ãã顧客ããã®æ³šæã«å¯ŸããŠããã絶察ã«åæ³çã«è¡ã£ãŠãããšèšããŸããã 圌ã¯äœãèããããªãã£ãã®ã§ãã€ã³ã¿ãŒãããèŠå¯ã§ç§ãã¡ãè è¿«ãå§ããŸããã ç§ãã¡ãå®å šã«ãªãŒãã³ã«è¡åããŠãããããéæ³ãªã¹ãã£ã³ã«åŸäºããŠããã°ã1æé以å ã«å šå¡ãæãŸã£ãŠããŸãããšãç解ããŠããªãã£ãã®ã¯ããã ã®çã£ã人ã§ãã

ãããã®ãããªç³ç«äººã¯ããã°ãã°ãã ã®æãè ã§ãã ãããã¯ãŒã¯ããã¹ãŠã®ããŒããã«ãŒã¿ãŒãã¹ã€ãããã»ãã·ã§ã³ã§è¡ãããŠããããã»ã¹ã®å€§éšåãåžžã«éãããŠãããæå·åã«ãã£ãŠä¿è·ãããŠããªãããšã圌ãã¯ç解ããŠããŸããã ãã以å€ã®å Žåã¯ãåã¢ã¯ã·ã§ã³ã«èš±å¯ãå¿ èŠãªå Žåãã€ã³ã¿ãŒãããã¯ãŸã£ããæ©èœããŸããã ã¯ã¬ãžããã«ãŒãæ å ±ãçãŸããããšãæããŠãã人ã¯ãã€ã³ã¿ãŒãããããŸã£ãã䜿çšããªãæ¹ãããã§ãããã ãããŠãããã¯ãæ¢åã®ã®ã£ãããåããããã«ããã€ã¹ãåçŽã«æ§æããããšãã§ããªããšããäºå®ãèæ¯ã«çºçããŸãã 圌ãã¯åœŒãããã¹ãŠã®äººã«éããããŸãŸã«ãã圌ããããã«ãŒã®é€é£ã«ãªã£ãããšã«é©ããŠããŸãã ããŠãªéèã°ã«ãŒãã®ã€ã³ãã©ã¯ãã¯ã©ã¹Aåœå®¶ä¿å®æœèšæ©åšãã«åé¡ãããŠããããã®æ©åšãžã®äžæ£ã¢ã¯ã»ã¹ã¯é¢é£æ³èŠå¶ã«ãã£ãŠçŠæ¢ãããŠããŸããããšããå 容ã§åãåã£ãæçŽããèŠãããããšæããŸãã ãã®äŒç€Ÿã¯éåœã«ãããèŠæ ãç§ãã¡ã«éã£ãã ãã§ãªããæçŽã§åœŒãã®è¡åã説æããã®ã§ãç§ãã¡ã¯æåã«ãã®æçŽããããã«ã€ããŠç¥ããŸããã ç§ã¯æåã«ãã€ã³ã¿ãŒãããã«ã¢ã¯ã»ã¹ããåæã«ãã¹ãŠã®æ©åšãç§å¯ã«ãããçµç¹å šäœã«äŒããŸããã éããããŒãã§å®è¡ã§ããªãå Žåããªãã€ã³ã¿ãŒãããã«è¡ãã®ã§ããïŒ
ç§ãã¡ã®ä»äºã®éèŠãªåŽé¢ã¯ãã€ã³ã¿ãŒããããããã€ããŒãšã®ç·å¯ãªååã§ãã ããã§ãªããã°ãå¹æçãªã¹ãã£ã³ã«æåããŸããã ã€ã³ã¿ãŒãããã»ãã¥ãªãã£ã«é¢ããç¡æçžè«ãæäŸããå¯ããããèŠæ ã®ãªã¹ãã®èª¿æŽãæ¯æŽããŸãã ã€ãŸãããããã€ããŒã¯ã誰ãããªãç§ãã¡ã«äžæºãèšã£ãããç解ããç§ãã¡ã«å¯Ÿããæ ¹æ ã®ãªãåçºãæåŠããŸãã ããããšäžç·ã«ããã§ãã¯ãããIPã¢ãã¬ã¹ã®ãªã¹ããå«ãSWIPãããžã§ã¯ããWho is Who on the Internetããäœæããã¹ãã£ã³ã®çŠæ¢ã䞻匵ãã人ã ãããã©ãã¯ãªã¹ããã«èŒããŸãã

æ··ä¹±ãé¿ãã代ããã«ãå¿åã®ä»®æ³å°çšVPSãµãŒããŒãäœæã§ããŸãã 次ã®å©ç¹ããããŸãã
- VPSãããã€ããŒã¯ããããã³ã€ã³ã§å°é¡ãæ¯æãããšãã§ããŸãã
- 調æ»åŸã«ã¢ã«ãŠã³ãããããã¯ãŒã¯ããåæããã ããªã®ã§ãèŠæ ãªãã§ã¹ãã£ã³ã§ããŸããããšãã°ãLinodeãã¹ãã£ã³ã°ã®VPSã§ã¯ã$ 50ãæ¯æã£ãçŽåŸã«ã¢ã«ãŠã³ããåé€ã§ããŸãã
- ãã®ãããªãããã€ããŒã®ååãªæ°ããä»®æ³ãµãŒããŒãè£ ã£ãŠåãã¹ãããŒãè©æ¬ºåž«ãæ¯æããŠããŸãã
masscanãã¯ãããžãŒã¯ã©ã®ãããªãã®ã§ããïŒ
nmapãŠãŒãã£ãªãã£ã«äŒŒãŠããŸããnmapãŠãŒãã£ãªãã£ã¯ãä»»æã®æ°ã®ãªããžã§ã¯ãã§IPãããã¯ãŒã¯ãã¹ãã£ã³ããããŒããšããã«å¯Ÿå¿ãããµãŒãã¹ã®ã¹ããŒã¿ã¹ãå€æããããã«èšèšãããŠããŸãã
- ããã®nmapãªãã·ã§ã³ã¯ãµããŒããããŠããŸããããšèšãããŠãããã®ãé€ãããã¹ãŠã®nmapãªãã·ã§ã³ã¯éšåçã«å解ã§ããŸãã
- äžéšã®ããŒã«ã䜿çšããå ŽåãåºåããŒã¿åœ¢åŒãnmapã«è¿ããšäŸ¿å©ã§ãã
- SCTPãããŒå¶åŸ¡ã§äŒéãããã³ã«ãã¹ãã£ã³ããããnmapãã€ããŒããšããŠUDPãŠãŒã¶ãŒããŒã¿ãããã³ã«ã䜿çšãããªã©ãå€ãã®æ©èœããµããŒããããŠããŸãã
ããããmasscanã¯nmapãšã¯ç°ãªããŸãã
- ãã¹ãã¢ããã¢ã¿ã€ã ã¢ãŒãã§ã¯ãªãããŒãã¢ããã¢ã¿ã€ã ã¢ãŒãã ã€ãŸããåããŒãã®çµæã¯æ€åºããããšããã«å ±åããããããã®çµæã¯ãã¹ãã䜿çšããŠäºãã«çµåãããŸããã ã€ãŸããããã°ã©ã ã¯ãªã¯ãšã¹ããéä¿¡ããã¬ã¹ãã³ã¹ãåä¿¡ããããã«æéãè²»ããå¿ èŠããããŸããã 10åã®ãªã¯ãšã¹ããš10åã®ã¬ã¹ãã³ã¹ãã¡ã¢ãªã«ä¿åããå¿ èŠããªããããåäœãéããªããŸãã
- éåæã«åäœããŸããéä¿¡ãããé åã¯èŠæ±ããäœæãããçµæã®é åã¯å¿çããäœæãããŸãã
- 1000åé«éã«ã¹ãã£ã³ããŸãã
Nmapã¯æé«ã®ã¹ãã£ããŒã§ããNSEã¹ã¯ãªãããšã³ãžã³ã¯éåžžã«æè»ã§ãããè€æ°ã®ãã¹ããåé¡ãªãã¹ãã£ã³ã§ããŸãã Masscanã¯å€§èŠæš¡ãªãããã¯ãŒã¯åãã«èšèšãããŠããããã®ããã°ã©ã ã¯ã¯ããã«é«éã§ã¹ã±ãŒã©ãã«ã§ãã
Masscanã«ã¯ç¬èªã®TCP / IPã¹ã¿ãã¯ããããŸãã
- æ¢åã®ã¹ã¿ãã¯ãšäžŠè¡ããŠåäœããŸãã
- ããã©ã«ãã¯åãã¢ãã¬ã¹ã§ãã
- ARPãããã¯ãŒã¯å±€ãããã³ã«ãšTCP RSTãã±ãããè€è£œããŸãã
ããããã¢ãã¬ã¹ã¹ããŒãã£ã³ã°ãããããã¹ããŒãã£ã³ã°æ»æã§ããã«ãŒæ»æãå®è¡ãããæ¹æ³ã§ãã ãã¹ãA-æ»æè ãæ»æãããã¹ãVãããã³ãã¹ãOïŒããã«ãŒãæ»æã«äœ¿çšããIPã¢ãã¬ã¹ïŒããããšããŸãã
ãã¹ãAã¯SYNãã±ããããã¹ãVã«éä¿¡ããŸããããªã¿ãŒã³ã¢ãã¬ã¹ã¯ãã®IPã¢ãã¬ã¹ã§ã¯ãªãããã¹ãOã®ã¢ãã¬ã¹ã瀺ããŸããæ»æãåãããã¹ãVã¯ãã¹ãOã«SYN / ACKãã±ããã§å¿çããŸãã ãã ãããã¹ãOã¯ãã¹ãAã«äœãéä¿¡ããªãã£ããããRSTãã±ããã§æ¥ç¶ãåæããå¿ èŠããããŸãã ãã¹ãOããã®ãããªãã±ãããéä¿¡ããªãã£ãã®ã¯ããã±ãããéè² è·ã«ãªã£ãŠãããããªãã«ãªã£ãŠããããSYN / ACKãã±ããããããã¯ãããã¡ã€ã¢ãŠã©ãŒã«ã§ä¿è·ãããŠããããã§ãã
ãã¹ãOãRSTãã±ãããéä¿¡ãããæ»æãäžæããªãã£ãå Žåãããã«ãŒãã¹ãAã¯ãã¹ãVãè£ ã£ãŠãã¹ãVãšå¯Ÿè©±ã§ããŸãããããã£ãŠããŠãŒã¶ãŒã®ãã¡ã€ã¢ãŠã©ãŒã«ãæ£ããæ§æãããŠããªããšãæ¿èªè ããã£ããã£æ€èšŒãªã©ã¯åœ¹ã«ç«ããªããªããŸãã
ãããã£ãŠãRSTãã±ããã¯IPæ¥ç¶ãéä¿¡ããä¿è·ããŸããã€ãŸããSYNé害ã§ãã±ããã«å¿çããŸãã 圌ãã®æ¯æŽã«ãããããŸããŸãªIPã¢ãã¬ã¹ãã¹ããŒãã£ã³ã°ããä¿è·ããããç¹å®ã®ç¯å²ã®ããŒãã«ã»ãã¥ãªãã£ãã£ã«ã¿ãŒãã€ã³ã¹ããŒã«ãããã§ããŸãã
ããã§ã¯ãmasscanã管çããããŒã ã«ã€ããŠè©±ããŸãããã
ã»ãã¥ãªãã£ãããã³ã«ã«éåããªãããã«ãè€æ°ã®ããã€ã¹ãã¹ãã£ã³ãããŸãã
- --è€æ°ã®ã³ã³ãã¥ãŒã¿ãŒãã¹ãã£ã³ããå¿ èŠãããå Žåãã·ã£ãŒã1/50ã䜿çšãããŸãã
- --source-ip 10.0.0.32-10.0.0.63ã¯ãã¹ãã£ã³ç¯å²ãåãã³ã³ãã¥ãŒã¿ãŒäžã®è€æ°ã®IPã¢ãã¬ã¹ã«æ¡åŒµããŸãã
- --source- ip 0.0.0.0-255.255.255.255ã¯äœ¿çšããªãã§ãã ããïŒ çµæãåŸ ããã«ãã³ã³ãã¥ãŒã¿ãŒãããªãŒãºããŸãã
åé¡ãåé¿ããããã«ãTCP / IPæ¥ç¶ãæåã§æ§æããå ŽåããããŸãã
- --source-ip 192.168.10.15;
- --éä¿¡å ããŒã4444;
- --router-mac 00-11-22-33-44-55 with--router-ip 192.168.10.1
ãããŒæ€èšŒããŒã ãè¡ãããšã¯æ¬¡ã®ãšããã§ãã
- TCPæ¥ç¶ã確ç«ããŸãã
- ãããã³ã«ã®ãã¥ãŒãªã¹ãã£ãã¯åæãå®è¡ããŸããã€ãŸããããŒã443ãã¹ãã£ã³ããŠãSSHããã³HTTPãæ¢ããŸããSSHããã³HTTPã¯ãã€ã³ã¿ãŒãããããã®ããŒãã«ã¢ãã¬ã¹æå®ããŸãã
çŸåšãNSEã¹ã¯ãªããã«äŒŒããã®ã䜿çšããŠããŸããããŸããªãCããŒã¹ã®ããã°ã©ãã³ã°ã«ç§»è¡ããŸãã
è² è·ãã¹ãã䜿çšããããšãã§ããŸãã ããã¯ããã¡ã€ã¢ãŠã©ãŒã«ã®ä¿è·ããçªç Žãããå¯èœæ§ããããããã»ãã¥ãªãã£ãæäŸããæ©èœã®ãã¹ãã«é¢é£ããŠããŸãã ãã®å Žåãã³ãã³ã--ç¡éã--ãããŒã--sourse-ip <range>ã¯ãå€æ°ã®ããã€ã¹ããã°ããã¹ãã£ã³ããã®ã«åœ¹ç«ã¡ãŸãã
éåžžã誰ãããã䜿çšããŸããããããã°ã©ã ã§ã¯çºä¿¡ãã€ããªãã¡ã€ã«ã䜿çšããå¯èœæ§ããããŸãããã®ããã次ã®ã³ãã³ãã䜿çšããŸãã
â oB foo.scan âoX foo.xml
次ã«ãå€æãå®è¡ãããŸãã
masscanâreadscan foo.scan âoX foo.xml
ãã®æ¹æ³ã¯ãããã³ã³ãã¯ããªã¹ãã£ã³ãæäŸããŸãã ããã«ãçºä¿¡ããŒã¿ã«ãšã©ãŒãããå Žåããã€ããªåœ¢åŒã§ä¿®æ£ããæ¹ãç°¡åã§ãã
ãã1ã€ã®äŸ¿å©ãªæ©èœã¯ããªãããŸãã¹ãã£ã³ã§ãã IPã¹ããŒãã£ã³ã°ã§ã¯ããã±ããæ¬äœã®IPã¢ãã¬ã¹ã眮ãæããŠãå¿çãã±ãããããã«ãŒã®ã¢ãã¬ã¹ã«ãã£ãŠååãããããã«ããŸãã ãã®ãã¯ãããžãŒã¯ãããã«ãŒãã€ãŒãµããããããã¯ãŒã¯äžã®ãã¹ãéã®ãã©ãã£ãã¯ãååããããã«äœ¿çšããŸãã
ãªãããŸãã®ã¹ãã£ã³ã¯æ¬¡ã®ãšããã§ãã
- ããšãã°ãAndroidãå®è¡ããŠããã¹ããŒããã©ã³ãªã©ã1ã€ã®IPã¢ãã¬ã¹ãæã€ãã±ãããåä¿¡ããŸãã
- åä¿¡ãããã±ããã®åž¯åå¹ ãçãã
- éä¿¡ãã£ã«ã¿ãŒãªãã§ããŒã¿ã»ã³ã¿ãŒãããã±ãããéä¿¡ããå Žåãcommand--source-ipã䜿çšãããšãå¥ã®IPã¢ãã¬ã¹ã®ã¹ããŒãã£ã³ã°ãã¹ãã£ã³ã§ããŸãã
ã¹ãã£ã³çµæã¯æ¬¡ã®ããã«ãªããŸãã æåã®å³ã§ã¯ãããã°ã©ã ã®ãŠã£ã³ããŠã衚瀺ããã2çªç®ã®å³ã§ã¯ããã®äœæ¥ã®çµæã衚瀺ãããŸãã
Heartbleedè åšãã§ãã¯ã®çµæã¯ã4æ10æ¥ã®æç¹ã§ã600,000ã®ã·ã¹ãã ã§è匱æ§ãæ€åºããã7æã«300,000ã®ã·ã¹ãã ãäŸç¶ãšããŠè匱ã§ããããã®ã»ãšãã©ãããŒããŠã§ã¢ããã€ã¹ïŒã³ã³ãã¥ãŒã¿ãŒãã«ãŒã¿ãŒããŠã§ãã«ã¡ã©èªäœïŒã§ãã£ãããšã瀺ããŠããŸãããã³ãµãŒããŒã ã€ãŸãããããã®è匱æ§ã¯è¡šç€ºãããŸãããDNSåã§ãã§ãã¯ãããšãIPã¢ãã¬ã¹ã«ããã¹ãã£ã³ã®ã¿ã圹ç«ã¡ãŸãã ãŸããã¡ã€ã³ãã¬ãŒã ïŒããŒã992ãä»ããTN3270 Telnet -over-SSLãªã©ã®å€§èŠæš¡ãªãã©ãŒã«ããã¬ã©ã³ããµãŒããŒïŒãã¹ãã£ã³ããŸããã@ mainframed767ãèŠãŠãIBMã¡ã€ã³ãµãŒããŒãŠãŒã¶ãŒã®èªèšŒãŠã£ã³ããŠãªã©ã®èå³æ·±ããã®ã確èªã§ããŸãã
3çªç®ã®å³ã¯ããããŒãã¹ãã£ã³ããçµæã瀺ããŠããŸãã ããã§ãç§ãã¡ã®ããã°ã©ã ã®å®éã®æ§åããèŠãããŸãã ãããè¡ãã«ã¯ãã¡ã€ã³ãŠã£ã³ããŠãéããã³ãã³ãã©ã€ã³ã䜿çšããŠã¹ãã£ã³ãããµãŒããŒã®ã¢ãã¬ã¹ãèšå®ããŸãã å Žåã«ãã£ãŠã¯ããµãŒããŒã¯å¿çããŸããã



ããã§ãPaulã¯èªåã®ãã°ã€ã³ã§ãã°ã€ã³ããŠãã¹ãã£ã³æ©èœãå®èšŒããããšããŸãã

ããŒã«ã¯ãããã°ã©ã ã®äœ¿çšã«ã€ããŠè³ªåãããå Žåã¯ãçŽæ¥åœŒã«é£çµ¡ããŠå¿ èŠãªèª¬æãåŸãããšãã§ãããšèšããŸãã äŸãšããŠãPaulã¯VNS 5900ãµãŒããŒãä»ããŠã€ã³ã¿ãŒããããã¯ããŒã«ããŸããããã«ã¯15ã20åããããŸãã
ãã®ããã°ã©ã ã®å©ç¹ã¯ããããã¯ãŒã¯ãŸãã¯åãããã¯ãŒã¯ããã€ã¹ã§ã®æ¿èªãå¿ èŠãšããã«ãè匱æ§ã®ãªã¹ããååŸã§ããããšã§ãã ã·ã¹ãã ãå éšããã§ã¯ãªããå€éšãããã¹ãããŸãã ã¹ã±ãŒãªã³ã°ã䜿çšãããšãã¯ã©ãŠããå«ãã€ã³ã¿ãŒããããããã¯ãŒã¯ã®èšå€§ãªé åããã§ãã¯ã§ãã1æéããã16ã»ã³ãæªæºã§ãã
çŸåšãããŒã80ãä»ããŠæ¯ç§10ãã±ããã§defconãããã¯ãŒã¯ã®äœéã¹ãã£ã³ãèšå®ããŠããŸãããçµæã¯ããã«ç»é¢ã«è¡šç€ºãããŸãã

çŸæç¹ã§ã¯ã察å¿ããIPã¢ãã¬ã¹ãæã€ä¿è·ãããŠããªãããã€ã¹ããŒãããããã¯ãŒã¯ã«ããã€ããããããããŸãã ãŸããããã«ãŒã¯ãããã®IPã¢ãã¬ã¹ã䜿çšããŠããªãããŸãæ»æãè¡ãããšãã§ããŸãã

ãã®æé ã¯ãã¹ãã£ã³ãããŠãããããã¯ãŒã¯ã®åäœã劚ããŸããããŠãŒã¶ãŒã¯ä»»æã®ã¢ããªã±ãŒã·ã§ã³ãå®è¡ã§ããŸãã ãããã£ãŠãdefconãããã¯ãŒã¯ã¹ãã£ã³ã«ã¯1å以äžããããããŒã80ãã¹ãã£ã³ããã ãã§æ¢åã®è匱æ§ããã¹ãŠç¹å®ããŸããããã±ãããµã€ãºãèšå®ããããšã§ãã¹ãã£ã³ãé«éåãŸãã¯äœéåã§ããŸãã masscanããã°ã©ã ã«ã€ããŠç¥ã£ãŠããã¹ããã¹ãŠã®ããšããäŒãããŸããã質åãããå Žåã¯ãé»åã¡ãŒã«ãŸãã¯twitter @erratarobããã³paulmã§ãåãåãããã ãã ã
ãæ»åšããã ãããããšãããããŸãã ç§ãã¡ã®èšäºã奜ãã§ããïŒ ããèå³æ·±ãè³æãèŠããã§ããïŒ æ³šæããããå人ã«æšå¥šããããšã§ãç§ãã¡ããµããŒãããŸããHabrãŠãŒã¶ãŒãç¬èªã«çºæãããšã³ããªãŒã¬ãã«ãµãŒããŒã®ãŠããŒã¯ãªé¡äŒŒåã§30ïŒ å²åŒïŒ VPSïŒKVMïŒE5-2650 v4ïŒ6ã³ã¢ïŒ10GB DDR4 240GB SSD 1Gbps 20ãã«ãŸãã¯ãµãŒããŒãåå²ããæ¹æ³ïŒ ïŒãªãã·ã§ã³ã¯RAID1ããã³RAID10ãæ倧24ã³ã¢ãæ倧40GB DDR4ã§å©çšå¯èœã§ãïŒã
Dell R730xdã¯2åå®ãã§ããïŒ ãªã©ã³ããšã¢ã¡ãªã«ã§249ãã«ããIntel Dodeca-Core Xeon E5-2650v4 128GB DDR4 6x480GB SSD 1Gbps 100 TVã2å°æã£ãŠããã ãã§ãïŒ ã€ã³ãã©ã¹ãã©ã¯ãã£ãã«ã®æ§ç¯æ¹æ³ã«ã€ããŠèªãã§ãã ããã ã¯ã©ã¹Rã¯ã1ç±³ãã«ã§9,000ãŠãŒãã®Dell R730xd E5-2650 v4ãµãŒããŒã䜿çšããŠããŸããïŒ